PT-2025-50321 · Microsoft+1 · Active Directory+1
Published
2025-12-10
·
Updated
2025-12-10
·
CVE-2025-13953
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GTT Tax Information System (affected versions not specified)
Description
The GTT Tax Information System application contains a bypass in its authentication method, specifically related to Active Directory (LDAP) login. Authentication is conducted via a local WebSocket, but the application does not validate the authenticity or origin of the received data. This allows an attacker with local machine or internal network access to impersonate the legitimate WebSocket and inject manipulated information. Successful exploitation enables an attacker to authenticate as any user in the domain without valid credentials, potentially compromising the confidentiality, integrity, and availability of the application and its data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Active Directory
Gtt Tax Information System